Quantcast
Channel: All ScreenOS Firewalls (NOT SRX) posts
Viewing all articles
Browse latest Browse all 2577

Re: VPN tunnel going up and down (how to check if ISP has block ESP traffic)

$
0
0

Hi,

 

Only adding the proxy-id will not help. We have to ensure the ICMP connectivity between 2 IPs, one IP behind each VPN gateway. In your VPN-monitor you need to specify a source and destination IP,  Netscreen will use the same source/destination IP in the PING and the IP behind the PA should respond to that ping. Otherwise it will fail.  You can use loopback interfaces on both the devices for this, assign them unused IPs/32 and configure the VPN Monitoring accordingly. Also, ensure you have routes/proxy-id etc to allow connectivity between these two IPs.

 

Thanks,

Vikas

 

 


Viewing all articles
Browse latest Browse all 2577

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>